Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

JADEPUFFER-Linked Attackers' Sophisticated AI-Orchestrated Attack on Microsoft Azure Highlights the Need for Enhanced Cloud Security Measures


Microsoft Azure was targeted by the JADEPUFFER threat actor in a sophisticated AI-orchestrated attack, highlighting the need for enhanced cloud security measures to keep pace with the evolving threat landscape. The attack, which involved the deletion of numerous Azure resources, underscores the importance of proper governance, visibility, and controls for AI agents operating within cloud environments.

  • Microsoft Azure was attacked by the JADEPUFFER threat actor, leveraging compromised service principals.
  • The attack exploited a known security flaw in Langflow (CVE-2025-3248) and used AI infrastructure to carry out complex operations.
  • The threat actor deleted numerous Azure resources, including storage accounts, SQL databases, and Virtual Machines.
  • The attack was facilitated by the exposure of client ID, client secret, and tenant ID in plaintext in a public GitHub issue.
  • The attack highlights the need for enhanced cloud security measures, particularly in the face of AI-orchestrated threats.
  • The attack underscores the importance of proper governance, visibility, and controls for AI agents operating within cloud environments.
  • The incident emphasizes the shared responsibility among cloud providers, customers, and security professionals to develop and implement effective security measures.



  • The recent attack on Microsoft Azure by the JADEPUFFER threat actor, leveraging compromised service principals, has shed light on the evolving landscape of cloud security threats. The attack, which took place in early June 2026, demonstrated the increasing sophistication of threat actors in exploiting vulnerabilities and carrying out complex operations within cloud environments.

    According to a report by Microsoft, the JADEPUFFER threat actor used compromised service principals to delete Azure resources, including Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services. The attack was facilitated by the exploitation of a known security flaw in Langflow (CVE-2025-3248), which allowed the threat actor to break in, harvest credentials, and burrow deeper into the network.

    The attack was further complicated by the use of an artificial intelligence (AI) infrastructure, scanning for nearly 180 file extensions spanning model checkpoints, vector databases, training datasets, and embedding indices, as well as macOS-centric files like Keychain stores, Xcode project files, and Apple Pages and Numbers documents. This AI-driven approach enabled the threat actor to coordinate complex post-compromise operations across cloud environments with greater speed and scale.

    Microsoft observed two compromised service principals linked to the same tenant, with one used for reconnaissance and resource discovery and the second for destructive operations and credential collection. The enumeration activity targeted Azure Virtual Machines, subscriptions, resource groups, and resources for close to 16 hours, carrying out over 300 read operations during the time period.

    The attack was eventually terminated after 16 hours, but not before the threat actor had successfully enumerated Azure App Service configuration stores, likely in an attempt to look for exposed credentials. The service principal then conducted over 150 destructive or credential collection-related operations in 35 minutes, involving over 100 storage account deletion attempts.

    Microsoft noted that most Azure Storage accounts targeted by the threat actor were successfully deleted, but Azure resource locks and storage account-level deletion protection blocked deletion attempts for few of the storage accounts. The company attributed the compromise of the service principal to the exposure of the client ID, client secret, and tenant ID in plaintext in a public GitHub issue by an employee of the impacted organization.

    The attack highlights the need for enhanced cloud security measures, particularly in the face of AI-orchestrated threats. Microsoft's detection of repeated probing from Storm-3168-linked infrastructure against several Azure App services for different customers added to the concerns, suggesting that the attacks are likely automated or scripted.

    The end goal of the attack was assessed to be ransomware-aligned, as it led to the deletion of numerous Azure resources in addition to backup and recovery-related resources, suggesting that the threat actor was looking to impair the victim's ability to recover from the destructive activity. However, no ransom note or successful data exfiltration was observed in connection with the intrusion.

    The attack has been described as an evolution of the JADEPUFFER threat actor's tradecraft, demonstrating the increasing sophistication of threat actors in exploiting vulnerabilities and carrying out complex operations within cloud environments. As the use of AI and machine learning (ML) technologies continues to grow, it is essential for cloud security measures to keep pace with these advancements.

    The attack also underscores the importance of proper governance, visibility, and controls for AI agents operating within cloud environments. As AI agents continue to gain access to sensitive systems and data, security teams must develop the necessary tools and strategies to monitor, authorize, and govern these agents.

    The incident serves as a reminder that the security of cloud environments is a shared responsibility among cloud providers, customers, and security professionals. As the threat landscape continues to evolve, it is crucial that all stakeholders work together to develop and implement effective security measures that can prevent such attacks in the future.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/JADEPUFFER-Linked-Attackers-Sophisticated-AI-Orchestrated-Attack-on-Microsoft-Azure-Highlights-the-Need-for-Enhanced-Cloud-Security-Measures-ehn.shtml

  • https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html

  • https://windowsforum.com/news/storm-3168-azure-attack-compromised-service-principals-delete-storage-accounts.446061/


  • Published: Mon Sep 28 05:34:33 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us